Are those parameters what is being shown after each cipher string, in small grey lettering? I'm getting "ECDH secp256r1" for every cipher in the Handshake Simulation. Is that the parameter that's being referred to?

The server rating guide would appear to contradict your answer. The "Key Exchange" section of the grade is described as including the strength of the server's private key itself, as well as the key exchange algorithm itself.

I can rephrase my question slightly -- The grades given for RSA key lengths are listed in the rating guide, but the equivalent grades for ECC keys are NOT listed.

Also, the description says that DH parameters will influence the grade, but does not say which parameters are graded as what.

I'm also unclear if the small text after the individual ciphers on the report correspond to the "DH parameters" which are being interrogated.

I think that's a fair criticism of the guide. But how I said it is precisely how it works. For DH parameters for DHE key exchange, you need to use at least a 2048 bits, and for ECDH parameters for ECDHE key exchange, you need to use at least a 384-bit curve. For RSA key exchange, you need to use at least a 2048-bit private key, which lines up with the grades for your certificates' key strength, as RSA key exchange uses the same key pair for both. I don't think DHE or ECDHE key exchange - or any other type of non-RSA key exchange - is considered at all in the guide, although the grading does exist in the code.